WSO2 APIKeys API

The APIKeys API from WSO2 — 16 operation(s) for apikeys.

OpenAPI Specification

wso2-apikeys-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: WSO2 API Manager - Admin Advanced Policy (Collection) Advanced Policy (Collection) APIKeys API
  description: "This document specifies a **RESTful API** for WSO2 **API Manager** - **Admin Portal**.\nPlease see [full OpenAPI Specification](https://raw.githubusercontent.com/wso2/carbon-apimgt/master/components/apimgt/org.wso2.carbon.apimgt.rest.api.admin.v1/src/main/resources/admin-api.yaml) of the API which is written using [OAS 3.0](http://swagger.io/) specification.\n\n# Authentication\nThe Admin REST API is protected using OAuth2 and access control is achieved through scopes. Before you start invoking\nthe the API you need to obtain an access token with the required scopes. This guide will walk you through the steps\nthat you will need to follow to obtain an access token.\nFirst you need to obtain the consumer key/secret key pair by calling the dynamic client registration (DCR) endpoint. You can add your preferred grant types\nin the payload. A sample payload is shown below.\n```\n  {\n  \"callbackUrl\":\"www.example.com\",\n  \"clientName\":\"rest_api_admin\",\n  \"owner\":\"admin\",\n  \"grantType\":\"client_credentials password refresh_token\",\n  \"saasApp\":true\n  }\n```\nCreate a file (payload.json) with the above sample payload, and use the cURL shown bellow to invoke the DCR endpoint. Authorization header of this should contain the\nbase64 encoded admin username and password.\n**Format of the request**\n```\n  curl -X POST -H \"Authorization: Basic Base64(admin_username:admin_password)\" -H \"Content-Type: application/json\"\n  \\ -d @payload.json https://<host>:<servlet_port>/client-registration/v0.17/register\n```\n**Sample request**\n```\n  curl -X POST -H \"Authorization: Basic YWRtaW46YWRtaW4=\" -H \"Content-Type: application/json\"\n  \\ -d @payload.json https://localhost:9443/client-registration/v0.17/register\n```\nFollowing is a sample response after invoking the above curl.\n```\n{\n\"clientId\": \"fOCi4vNJ59PpHucC2CAYfYuADdMa\",\n\"clientName\": \"rest_api_admin\",\n\"callBackURL\": \"www.example.com\",\n\"clientSecret\": \"a4FwHlq0iCIKVs2MPIIDnepZnYMa\",\n\"isSaasApplication\": true,\n\"appOwner\": \"admin\",\n\"jsonString\": \"{\\\"grant_types\\\":\\\"client_credentials password refresh_token\\\",\\\"redirect_uris\\\":\\\"www.example.com\\\",\\\"client_name\\\":\\\"rest_api_admin\\\"}\",\n\"jsonAppAttribute\": \"{}\",\n\"tokenType\": null\n}\n```\nNote that in a distributed deployment or IS as KM separated environment to invoke RESTful APIs (product APIs), users must generate tokens through API-M Control Plane's token endpoint.\nThe tokens generated using third party key managers, are to manage end-user authentication when accessing APIs.\n\nNext you must use the above client id and secret to obtain the access token.\nWe will be using the password grant type for this, you can use any grant type you desire.\nYou also need to add the proper **scope** when getting the access token. All possible scopes for Admin REST API can be viewed in **OAuth2 Security** section\nof this document and scope for each resource is given in **authorizations** section of resource documentation.\nFollowing is the format of the request if you are using the password grant type.\n```\ncurl -k -d \"grant_type=password&username=<admin_username>&password=<admin_passowrd>&scope=<scopes seperated by space>\"\n\\ -H \"Authorization: Basic base64(cliet_id:client_secret)\"\n\\ https://<host>:<server_port>/oauth2/token\n```\n**Sample request**\n```\ncurl https://localhost:9443/oauth2/token -k \\\n-H \"Authorization: Basic Zk9DaTR2Tko1OVBwSHVjQzJDQVlmWXVBRGRNYTphNEZ3SGxxMGlDSUtWczJNUElJRG5lcFpuWU1h\" \\\n-d \"grant_type=password&username=admin&password=admin&scope=apim:admin apim:tier_view\"\n```\nShown below is a sample response to the above request.\n```\n{\n\"access_token\": \"e79bda48-3406-3178-acce-f6e4dbdcbb12\",\n\"refresh_token\": \"a757795d-e69f-38b8-bd85-9aded677a97c\",\n\"scope\": \"apim:admin apim:tier_view\",\n\"token_type\": \"Bearer\",\n\"expires_in\": 3600\n}\n```\nNow you have a valid access token, which you can use to invoke an API.\nNavigate through the API descriptions to find the required API, obtain an access token as described above and invoke the API with the authentication header.\nIf you use a different authentication mechanism, this process may change.\n\n# Try out in Postman\nIf you want to try-out the embedded postman collection with \"Run in Postman\" option, please follow the guidelines listed below.\n* All of the OAuth2 secured endpoints have been configured with an Authorization Bearer header with a parameterized access token. Before invoking any REST API resource make sure you run the `Register DCR Application` and `Generate Access Token` requests to fetch an access token with all required scopes.\n* Make sure you have an API Manager instance up and running.\n* Update the `basepath` parameter to match the hostname and port of the APIM instance.\n\n[![Run in Postman](https://run.pstmn.io/button.svg)](https://app.getpostman.com/run-collection/32294946-71bea2bc-f808-4208-a4f6-861ede6f0434)\n"
  contact:
    name: WSO2
    url: https://wso2.com/api-manager/
    email: architecture@wso2.com
  license:
    name: Apache 2.0
    url: http://www.apache.org/licenses/LICENSE-2.0.html
  version: v4
servers:
- url: https://apis.wso2.com/api/am/admin/v4
tags:
- name: APIKeys
paths:
  /api-keys:
    get:
      tags:
      - APIKeys
      summary: Get all API Keys
      description: 'Retrieve all API Keys.

        '
      operationId: getAllAPIKeys
      responses:
        200:
          description: 'OK.

            API keys returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyList'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:admin
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X GET "https://127.0.0.1:9443/api/am/admin/v4/api-keys"'
  /api-keys/revoke:
    post:
      tags:
      - APIKeys
      summary: Revoke an API Key
      description: 'Revoke an API Key for the API

        '
      operationId: revokeAPIKeyFromAdmin
      requestBody:
        description: 'API key revoke object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyRevokeRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key revoked successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:admin
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://127.0.0.1:9443/api/am/admin/v4/api-keys/ght65523-7650-4255-84fa-6cb171c1f779/d7cf8523-9180-4255-84fa-6cb171c1f779/PRODUCTION/revoke"'
  /apis/{apiId}/api-keys/generate:
    post:
      tags:
      - APIKeys
      summary: Generate API Key
      description: 'Generate a self contained API Key for the API

        '
      operationId: generateApiBoundApiKey
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key generation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIAPIKeyGenerateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key generated.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKey_2'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/generate"'
  /apis/{apiId}/api-keys/regenerate:
    post:
      tags:
      - APIKeys
      summary: Regenerate API Key
      description: 'Regenerate a self contained API Key for the API specified by the key UUID

        '
      operationId: regenerateAPIBoundAPIKey
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key renewal request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyRenewRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key regenerated successfully.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKey_2'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/regenerate"'
  /apis/{apiId}/api-keys:
    get:
      tags:
      - APIKeys
      summary: Get API Key(s) of a Given API
      description: 'Retrieve self contained API Key(s) for the API.

        '
      operationId: getAPIBoundAPIKeys
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-None-Match'
      responses:
        200:
          description: 'OK.

            API key(s) of a given API are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIAPIKeyList'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X GET "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys"'
  /apis/{apiId}/api-keys/revoke:
    post:
      tags:
      - APIKeys
      summary: Revoke API Key
      description: 'Revoke a self contained API Key for the API specified by the key UUID

        '
      operationId: revokeAPIBoundAPIKey
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key revocation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIAPIKeyRevokeRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key revoked successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/revoke"'
  /apis/{apiId}/api-keys/associate:
    post:
      tags:
      - APIKeys
      summary: Create an association for the API Key
      description: 'Create an association for a self contained API Key for the API

        '
      operationId: associateAPIKey
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key association request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIAPIKeyAssociateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key associated successfully.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyAssociation'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/associate"'
  /apis/{apiId}/api-keys/dissociate:
    post:
      tags:
      - APIKeys
      summary: Remove an Association for the API Key
      description: 'Remove an association a self contained API Key for the API specified by the key UUID

        '
      operationId: dissociateAPIKey
      parameters:
      - $ref: '#/components/parameters/apiId'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key dissociation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyDissociateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Removed association for the Api key successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/apis/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/dissociate"'
  /applications/{applicationId}/api-keys/{keyType}/generate:
    post:
      tags:
      - APIKeys
      summary: Generate API Key
      description: 'Generate a self contained API Key for the application

        '
      operationId: applicationsApplicationIdApiKeysKeyTypeGeneratePost
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key generation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyGenerateRequest'
        required: false
      responses:
        200:
          description: 'OK.

            Api key generated.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKey_2'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/generate"'
  /applications/{applicationId}/api-keys/{keyType}/regenerate:
    post:
      tags:
      - APIKeys
      summary: Regenerate API Key
      description: 'Regenerate a self contained API Key for the application specified by the key UUID

        '
      operationId: regenerateAppBoundAPIKey
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key renewal request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyRenewRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key regenerated successfully.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKey_2'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/regenerate"'
  /applications/{applicationId}/api-keys/{keyType}:
    get:
      tags:
      - APIKeys
      summary: Get API Key(s) of a Given Type
      description: 'Retrieve self contained API Key(s) for the application specifying the key type in the URI.

        '
      operationId: getAppBoundAPIKeys
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-None-Match'
      responses:
        200:
          description: 'OK.

            API key(s) of given type are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyList_2'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X GET "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION"'
  /applications/{applicationId}/api-keys/{keyType}/revoke:
    post:
      tags:
      - APIKeys
      summary: Revoke API Key
      description: 'Revoke a self contained API Key for the application

        '
      operationId: applicationsApplicationIdApiKeysKeyTypeRevokePost
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key revoke request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyRevokeRequest_2'
        required: true
      responses:
        200:
          description: 'OK.

            Api key revoked successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/revoke"'
  /applications/{applicationId}/api-keys/{keyType}/subscriptions:
    get:
      tags:
      - APIKeys
      summary: Get Subscribed APIs with API Key(s) of a Given Type
      description: 'Retrieve subscribed APIs with non-associated API Key(s) for the application specifying the key type in the URI.

        '
      operationId: getSubscribedAPIsWithAPIKeys
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-None-Match'
      responses:
        200:
          description: 'OK.

            Subscribed APIs along with the non-associated API key(s) of given type are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SubscribedAPIWithApiKeyList'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X GET "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/subscriptions"'
  /applications/{applicationId}/api-keys/{keyType}/associate:
    post:
      tags:
      - APIKeys
      summary: Associate an API Key to the Application
      description: 'Create an association to a self contained API Key for the application

        '
      operationId: associateAPIKeyToApp
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key association request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AppAPIKeyAssociateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Api key associated successfully.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyAssociation'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/associate"'
  /applications/{applicationId}/api-keys/{keyType}/dissociate:
    post:
      tags:
      - APIKeys
      summary: Remove the association of the API Key to the Application
      description: 'Remove the association to a self contained API Key for the application

        '
      operationId: dissociateAPIKeyFromApp
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-Match'
      requestBody:
        description: 'API Key dissociation request object

          '
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIKeyDissociateRequest'
        required: true
      responses:
        200:
          description: 'OK.

            Removed association for the API key successfully.

            '
          content: {}
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X POST -d @data.json "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/dissociate"'
  /applications/{applicationId}/api-keys/{keyType}/associations:
    get:
      tags:
      - APIKeys
      summary: Get API Key associations of a Given Type
      description: 'Retrieve API key associations for the application specifying the key type in the URI.

        '
      operationId: getAPIKeyAssociationsForApp
      parameters:
      - $ref: '#/components/parameters/applicationId'
      - $ref: '#/components/parameters/keyType'
      - $ref: '#/components/parameters/If-None-Match'
      responses:
        200:
          description: 'OK.

            API key associations of given type are returned.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyAssociationList'
        400:
          $ref: '#/components/responses/BadRequest'
        404:
          $ref: '#/components/responses/NotFound'
        412:
          $ref: '#/components/responses/PreconditionFailed'
      security:
      - OAuth2Security:
        - apim:subscribe
        - apim:app_manage
        - apim:api_key
      x-code-samples:
      - lang: Curl
        source: 'curl -k -H "Authorization: Bearer ae4eae22-3f65-387b-a171-d37eaa366fa8" -H "Content-Type: application/json" -X GET "https://localhost:9443/api/am/devportal/v3/applications/16cd2684-9657-4a01-a956-4efd89e96077/api-keys/PRODUCTION/associations"'
components:
  schemas:
    SubscribedAPIWithApiKeyList:
      title: Subscribed APIs with non-associated API keys
      type: object
      properties:
        count:
          type: integer
          description: 'Number of subscribed APIs with API keys returned.

            '
          example: 1
        list:
          type: array
          items:
            $ref: '#/components/schemas/APIWithKeyInfo'
    APIKeyAssociationList:
      title: API Key Associations List
      type: object
      properties:
        count:
          type: integer
          description: 'Number of API key associations returned.

            '
          example: 1
        list:
          type: array
          items:
            $ref: '#/components/schemas/APIKeyAssociationInfo'
    ErrorListItem:
      title: Description of individual errors that may have occurred during a request.
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
          description: Error code
        message:
          type: string
          description: 'Description about individual errors occurred

            '
    APIKeyRenewRequest:
      title: API Key renewal request object
      type: object
      required:
      - keyUUID
      properties:
        keyUUID:
          type: string
          description: The UUID of the API key
    Error:
      title: Error object returned with 4XX HTTP status
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: integer
          description: Error code
          format: int64
        message:
          type: string
          description: Error message.
        description:
          type: string
          description: 'A detail description about the error message.

            '
        moreInfo:
          type: string
          description: 'Preferably an url with more details about the error.

            '
        error:
          type: array
          description: 'If there are more than one error list them out.

            For example, list out validation errors by each field.

            '
          items:
            $ref: '#/components/schemas/ErrorListItem'
    APIKeyInfo:
      title: API Key details to invoke APIs
      type: object
      properties:
        keyUUID:
          type: string
          description: The UUID of the API key
        keyName:
          type: string
          description: API Key name
          example: Test_Key
        issuedOn:
          type: integer
          format: int64
          description: Created Time
          example: 3600
        validityPeriod:
          type: integer
          format: int64
          example: 3600
        lastUsed:
          type: integer
          format: int64
          description: Last used time as epoch milliseconds.
          example: 3600
    APIAPIKeyGenerateRequest:
      title: API Key generation request object
      type: object
      properties:
        keyName:
          type: string
          description: API Key name
          example: Test_Key
        keyType:
          type: string
          description: Type of the API key
          example: PRODUCTION
          enum:
          - PRODUCTION
          - SANDBOX
        validityPeriod:
          type: integer
          description: API key validity period
          format: int64
          example: 3600
        additionalProperties:
          type: object
          properties: {}
          description: Additional parameters if Authorization server needs any
    APIKeyAssociation:
      title: API Key association
      type: object
      properties:
        keyName:
          type: string
          description: API Key name
          example: Test_Key
        apiName:
          type: string
          description: API name
          example: NotificationAPI
        applicationName:
          type: string
          description: Application name
          example: DefaultApplication
    APIKeyList:
      title: API Keys List
      type: object
      properties:
        count:
          type: integer
          description: 'Number of API keys returned.

            '
          example: 1
        list:
          type: array
          items:
            $ref: '#/components/schemas/APIKey'
    APIAPIKeyInfo:
      title: API Key details to invoke APIs
      type: object
      properties:
        keyUUID:
          type: string
          description: The UUID of the API key
        keyName:
          type: string
          description: API Key name
          example: Test_Key
        associatedApp:
          type: string
          description: Associated application
          example: DefaultApplication
        issuedOn:
          type: integer
          format: int64
          description: Created Time
          example: 2026-02-06 23:45:07
        validityPeriod:
          type: integer
          format: int64
          example: 3600
        lastUsed:
          type: integer
          format: int64
          description: Last used time as epoch milliseconds.
          example: 2026-02-06 23:45:07
    APIKeyGenerateRequest:
      title: API Key generation request object
      type: object
      properties:
        keyName:
        

# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/wso2/refs/heads/main/openapi/wso2-apikeys-api-openapi.yml